Tracking heartbeat across clients
Events received and the latest event time for every client over a trailing window, in one call. The agency form of GET /client/v1/locations/last-event. Every client in the roster is returned: one with no events in the window has events 0 and last_event_at null, which usually means a missing snippet or no traffic.
curl -X GET "https://mythic-analytics.gulp.workers.dev/client/v1/agency/last-event?location_ids=loc_abc123%2Cloc_def456&hours_back=24" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN"
import requests
import json
url = "https://mythic-analytics.gulp.workers.dev/client/v1/agency/last-event?location_ids=loc_abc123%2Cloc_def456&hours_back=24"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://mythic-analytics.gulp.workers.dev/client/v1/agency/last-event?location_ids=loc_abc123%2Cloc_def456&hours_back=24", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://mythic-analytics.gulp.workers.dev/client/v1/agency/last-event?location_ids=loc_abc123%2Cloc_def456&hours_back=24", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://mythic-analytics.gulp.workers.dev/client/v1/agency/last-event?location_ids=loc_abc123%2Cloc_def456&hours_back=24')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
response = http.request(request)
puts response.body
{
"success": true,
"data": {
"hours_back": 24,
"locations": [
{
"location_id": "example_string",
"name": "Rockwell Supply",
"events": 425,
"last_event_at": "2026-10-06T00:42:02Z"
}
]
}
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Too Many Requests",
"message": "Rate limit exceeded. Please try again later",
"code": 429,
"retryAfter": 3600
}
{
"error": "Error",
"message": "`stats_failed`, `health_failed`, or `usage_failed` — the upstream analytics query failed. Retry.",
"code": 502
}
/client/v1/agency/last-event
Target server for requests. Edit to use your own host.
Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.
ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.Comma-separated location ids to narrow the roster. Every id must belong to this agency — a foreign id is 403 location_not_linked, never a silent empty result. Required in batches of up to 100 when the agency has more than 100 locations.
Lookback window in hours (1–720).
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.
Query Parameters
Comma-separated location ids to narrow the roster. Every id must belong to this agency — a foreign id is 403 location_not_linked, never a silent empty result. Required in batches of up to 100 when the agency has more than 100 locations.
loc_abc123,loc_def456Lookback window in hours (1–720).